Sub-processors
The third parties that process customer data on our behalf, what each one does, and where each one sits.
Effective date: September 20, 2026
Version 1.3, last updated September 20, 2026.
This page lists the Sub-processors that mailkube engages to process Customer Personal Data on your behalf. It restates the list in Section 5 of the Data Processing Addendum, which remains the authoritative version, and adds the contracting entity, processing location, and transfer safeguard for each one.
Mailkube imposes on each Sub-processor data protection obligations equivalent to those in the Addendum, and remains fully liable to the Customer for any failure by a Sub-processor to meet them. Where a Sub-processor has a parent entity in the United States, the transfer is governed by the Standard Contractual Clauses, as described in Section 8 of the Addendum.
Mailkube gives notice by email to the Customer’s organization owners and admins at least 14 days before it adds or replaces a Sub-processor, and the Customer may object within that period. The process, including the right to terminate with a pro-rata refund where an objection cannot be resolved, is set out in Section 5 of the Addendum.
Current Sub-processors
Each entry states three separate things: which legal entity we contract with, where the processing takes place, and what safeguards the transfer where the contracting entity is outside the European Union.
OVH. Infrastructure hosting. Processes and stores all Customer Personal Data described in Exhibit A of the Addendum. Contracting entity: OVH US LLC, 11950 Democracy Drive, Suite 300, Reston, VA 20190, United States, a subsidiary of the French OVHcloud group. Processing location: European Union. Transfer safeguard: Customer Personal Data remains stored in the European Union. The transfer to the contracting entity is covered by the Standard Contractual Clauses executed as part of that entity’s data processing agreement.
Cloudflare. Reverse proxy, TLS termination, content delivery, R2 object storage, and DNS. Processes connection data (IP addresses and request metadata) in transit, and stores content at rest. Contracting entity: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Processing location: object storage is configured to the European Union. Reverse proxy and content delivery run on a global network, so connection data may be handled at the point of presence nearest the visitor. Transfer safeguard: Standard Contractual Clauses concluded between mailkube and Cloudflare.
Sentry. Error monitoring. Processes technical error diagnostics from our backend services. Session replay in the dashboard is a separate, consent-gated tool for which we act as controller; see the next section. Contracting entity: Functional Software, Inc., trading as Sentry, 45 Fremont Street, San Francisco, CA 94105, USA. Processing location: Sentry’s European Union region. Transfer safeguard: Standard Contractual Clauses concluded between mailkube and Sentry.
Atlassian. Support ticketing through Jira. Processes personal data contained in support requests raised through the Service, which may include Customer Personal Data where you include it in a request. The same Jira instance also holds our early access waitlist, which is our own controller-side data rather than Customer Personal Data and is described in Section 4 of the Privacy Policy. Contracting entity: Atlassian Pty Ltd, Level 6, 341 George Street, Sydney NSW 2000, Australia. Processing location: determined by the regional hosting configuration of our Jira Cloud instance. Transfer safeguard: Standard Contractual Clauses concluded between mailkube and Atlassian.
Not sub-processors
Some third parties process personal data in connection with the Service but do not process Customer Personal Data on Mailkube’s behalf. They are independent controllers, tools Mailkube uses as a controller in its own right, or processors of data for which Mailkube is itself the controller rather than a processor, and they are disclosed in the Privacy Policy rather than here.
Stripe processes payments and billing data for Mailkube’s transactions. Mail Tactic Corporation is the seller of record, so Stripe is engaged by Mailkube rather than selling to the Customer in its own name. Stripe acts in two roles at the same time: it carries out payment instructions on Mailkube’s behalf as a processor, and it processes the same payment data as an independent controller for fraud prevention, anti-money-laundering screening, its obligations to banks and card networks, and its own regulatory duties. Neither role reaches Customer Personal Data. What Stripe receives is the Customer’s own billing information, being the organization or business name, the billing email address, the billing address, and the tax identifier where one is given, together with the card details the payer enters on Stripe’s own checkout page, which do not pass through Mailkube’s systems. The Customer’s contacts, recipients, and message content are never sent to it. Mailkube is the controller of that billing data under Section 2 of the Addendum, and a Sub-processor under Section 5 is a processor of Customer Personal Data, which is why Stripe is listed here and not above. Contracting entity: Stripe, LLC, United States. The transfer is covered by the Standard Contractual Clauses in Stripe’s data processing agreement.
Google (Google Analytics 4 and Firebase) and Amplitude are Mailkube’s own analytics tools. They receive data about Mailkube’s website visitors and account holders, not the Customer’s contacts or recipients. Amplitude is limited to the account holder’s own identity and dashboard usage. Firebase delivers realtime change notifications to the logged-in dashboard; its documents carry only internal record identifiers and counters, never message content or recipient data, and the browser’s direct connection to Google exposes connection data such as the IP address.
Cloudflare appears in both lists, for two separate roles. It is a sub-processor of Customer data, as set out above, because it runs the edge and content delivery the Service is served through. It is separately Mailkube’s own security tool: Cloudflare Turnstile protects Mailkube’s website forms and its registration page from automated abuse, and the data that reaches it there is website-visitor data rather than the Customer’s contacts or recipients. The Standard Contractual Clauses recorded above cover both roles.
Prighter holds Mailkube’s statutory representation in the European Union through two companies of the same group, both in Vienna: Prighter EU Rep GmbH under Article 27 GDPR and Prighter DSA GmbH under Article 13 of the Digital Services Act. Neither is a sub-processor. Where a data subject writes to the representative, what reaches Prighter is the copy that person chooses to send, not access to a Customer’s data held in the Service, and Prighter acts under Mailkube’s own statutory mandate rather than on a Customer’s instructions. Prighter is a processor of the correspondence Mailkube receives as a controller, and the Standard Contractual Clauses in its terms of service cover that role. The contrary view is worth stating: recipients of Customer mail are told they may write to the representative, and their data is Customer Personal Data everywhere else in these documents. Mailkube’s position rests on what the representative actually receives, which is a volunteered copy and nothing more.
Sentry session replay in the dashboard is also a controller-side tool. It records a masked reconstruction of an account holder’s own dashboard session to help diagnose errors, runs only after that person consents, and does not process the Customer’s contacts or recipients. Reports from the dashboard, including this one, are relayed to Sentry through Mailkube’s own servers rather than sent from the browser directly, and the same redaction applied to server-side error reports is applied to them on the way. This is separate from the backend error monitoring listed above, which is a sub-processor of Customer Personal Data.
Changes to this page
Section 5 of the Addendum remains the authoritative statement of the list for contractual purposes. This page is kept in step with it, and both are updated together whenever a Sub-processor is added or replaced.